PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.
Conclusion & alert: CVE-2023-44216 is rated High Exploit Risk (64/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.81%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.31% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.49% | 1.81% | +1.31% |
| 2 | 2025-12-28 | 0.41% | 0.49% | +0.08% |
| 3 | 2025-12-27 | — | 0.41% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
1.6 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2023-44216 medium priority: Ubuntu including 33 source packages (nvidia-graphics-drivers-304, nvidia-graphics-drivers-304-updates, …), 297 status rows across 9 suites (bionic, focal, jammy, lunar, mantic, noble, trusty, upstream, xenial): DNE 128, not-affected 111, ignored 58. | https://ubuntu.com/security/CVE-2023-44216 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canonical | ubuntu_linux | 22.04 | cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:* |
| amd | ryzen_7_4800u | — | cpe:2.3:h:amd:ryzen_7_4800u:-:*:*:*:*:*:*:* |
| intel | core_i7-10510u | — | cpe:2.3:h:intel:core_i7-10510u:-:*:*:*:*:*:*:* |
| intel | core_i7-12700k | — | cpe:2.3:h:intel:core_i7-12700k:-:*:*:*:*:*:*:* |
| intel | core_i7-8700 | — | cpe:2.3:h:intel:core_i7-8700:-:*:*:*:*:*:*:* |
| microsoft | windows_11 | — | cpe:2.3:o:microsoft:windows_11:-:*:*:*:professional:*:*:* |
| intel | core_i7-10610u | — | cpe:2.3:h:intel:core_i7-10610u:-:*:*:*:*:*:*:* |
| microsoft | windows_11 | — | cpe:2.3:o:microsoft:windows_11:-:*:*:*:home:*:*:* |
| intel | core_i7-11800h | — | cpe:2.3:h:intel:core_i7-11800h:-:*:*:*:*:*:*:* |
| nvidia | geforce_rtx_3060 | — | cpe:2.3:h:nvidia:geforce_rtx_3060:-:*:*:*:*:*:*:* |
| microsoft | windows_10 | — | cpe:2.3:o:microsoft:windows_10:-:*:*:*:pro:*:*:* |
| amd | ryzen_5_7600x | — | cpe:2.3:h:amd:ryzen_5_7600x:-:*:*:*:*:*:*:* |
| nvidia | geforce_rtx_2080_super | — | cpe:2.3:h:nvidia:geforce_rtx_2080_super:-:*:*:*:*:*:*:* |
| apple | macos | 13.1 | cpe:2.3:o:apple:macos:13.1:*:*:*:*:*:*:* |
| apple | m1_mac_mini | — | cpe:2.3:h:apple:m1_mac_mini:-:*:*:*:*:*:*:* |
| android | 13.0 | cpe:2.3:o:google:android:13.0:*:*:*:*:*:*:* | |
| pixel_6 | — | cpe:2.3:h:google:pixel_6:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://arstechnica.com/security/2023/09/gpus-from-all-major-suppliers-are-vulnerable-to-new-pixel-stealing-attack/ | Press/Media Coverage Third Party Advisory |
| https://blog.imaginationtech.com/introducing-pvric4-taking-image-compression-to-the-next-level/ | Press/Media Coverage |
| https://blog.imaginationtech.com/reducing-bandwidth-pvric/ | Press/Media Coverage |
| https://github.com/UT-Security/gpu-zip | Third Party Advisory |
| https://news.ycombinator.com/item?id=37663159 | Issue Tracking |
| https://www.bleepingcomputer.com/news/security/modern-gpus-vulnerable-to-new-gpuzip-side-channel-attack/ | Press/Media Coverage |
| https://www.hertzbleed.com/gpu.zip/ | Technical Description |
| https://www.hertzbleed.com/gpu.zip/GPU-zip.pdf | Exploit |
| https://www.w3.org/TR/filter-effects-1/ | Exploit |